">

If a website is pretending to be a legitimate business, asking for money under false pretenses, or trying to collect passwords or identity documents, stop using it. For U.S. consumers, no single agency or form can take down every scam site. Use the channel that matches the harm:

What happened Report or contact first What that route may do
Money is pending or already gone Your bank, card issuer, or payment app Review the transaction, apply its fraud or dispute process, and possibly attempt a reversal
Phishing, account theft, crypto fraud, or another online crime The FBI's Internet Crime Complaint Center Collect the complaint and share it with FBI offices and law-enforcement partners
A fake store or deceptive online business The FTC's ReportFraud portal Add the complaint to consumer-fraud information used by law enforcement
A phishing or malware warning is needed Report the exact page to Google Safe Browsing and Bing Help the services assess browser warnings or search treatment
The website should be investigated by its infrastructure provider The host, registrar, CDN, or security provider Give the provider a chance to investigate and act under its abuse policy

You can use several routes. Keep the facts, URLs, dates, and payment details accurate and consistent. None of these reports guarantees a takedown or a refund.

1. Save evidence before the site changes

Scam sites can disappear, change their checkout page, or move to another domain. Capture what you can without signing in again, downloading files, or bypassing a browser warning.

Record:

Don't send a password, full card number, Social Security number, or identity document just because a page requests it. If an official reporting form requires sensitive information, first check that you're on the correct government or company website. Redact unnecessary details from screenshots and attachments.

If your browser shows a security warning, don't bypass it to gather more evidence. A description of the page and a screenshot may be enough.

2. Protect your money and accounts

A report to the FTC, IC3, a search engine, or a host doesn't stop a payment that is still processing. Contact the bank, card issuer, or payment service through the number on your card, its official app, or a statement - not through contact information supplied by the site.

Explain what happened and ask which process applies:

Keep the case number, department name, and date for every call or submission. Don't pay a supposed recovery agent to release a refund. Guaranteed recovery promises are a common follow-up scam.

If you entered a password, change it from a device you trust and change it anywhere else you reused it. Turn on multifactor authentication, starting with your email account. If you downloaded a file or gave someone remote access, stop using that device for banking until it has been checked.

3. Report the site to U.S. agencies

FTC: fake stores and deceptive businesses

Use the FTC's ReportFraud portal for fake online stores, non-delivery, deceptive offers, impersonation, and other consumer scams.

Include:

The FTC uses complaints to identify patterns and share information with law enforcement. Treat the submission as a formal record, not as a promise that the FTC will resolve your individual dispute or recover your money.

IC3: online and cyber-enabled crime

File an IC3 complaint when the site is connected to phishing, account compromise, online fraud, cryptocurrency theft, a fraudulent investment, extortion, or another cyber-enabled crime. Technical and financial details are more useful than only saying that the site "looks fake."

Include information such as:

The FBI's cyber guidance directs people to a local FBI field office or its tips route for an ongoing crime, threat to life, or national-security matter. Don't wait for an IC3 response during an emergency. IC3 also says that its high complaint volume means it can't respond directly to every submission, so not hearing back doesn't show that the report was ignored.

4. Report the exact page to search and security services

Submit the specific suspicious URL, not only the site's domain or business name.

These reports may contribute to browser or search warnings. They generally don't remove the site from its host, cancel the domain registration, or refund a purchase. A fake store that doesn't collect passwords or deliver malware may need to be reported primarily to the FTC, payment provider, host, and registrar.

Describe the conduct specifically. For example: "The checkout page collects card details, but the business information appears to be copied from another company." That gives a reviewer more to assess than "this is a scam." Don't report a competitor or business merely because you dislike its prices or policies.

5. Report the host, registrar, or Cloudflare

The domain registrar manages the domain name. The hosting provider stores the website. A content delivery or security service may sit between visitors and the actual host. These can be different companies, so a report to one may not reach the others.

Use public domain-registration or DNS information to identify the registrar and, if possible, the hosting provider. Find an abuse or security contact on each provider's official website.

Include:

A concise report can look like this:

Subject: Suspected phishing or fraudulent website: [domain]
Pages: [exact page addresses]
Observed conduct: [specific facts, dates, and misleading claims]
Evidence: [screenshots, emails, payment records]
Requested action: Please investigate under your abuse policy.

Don't include passwords, executable files, or unnecessary personal data. Avoid threats and repeated duplicate submissions; they can make a legitimate abuse report harder to review.

Cloudflare may not be the origin host

If a domain uses Cloudflare, Cloudflare may provide DNS, caching, proxy, or security services while another company hosts the content. Submit the report through Cloudflare's abuse form and separately report the site to the origin host if you can identify it. A Cloudflare report doesn't guarantee that the site will go offline.

What ICANN can and can't do

ICANN's security-issue guidance points people to its contractual compliance complaint process for problems involving domain registration, phishing, spam, WHOIS accuracy, or a registrar or registry. Use that route when the concern involves the registrar or registry's conduct.

ICANN isn't the website's host and isn't a universal consumer takedown service. Report the site's content, fraud, or payment activity to the relevant host, platform, agency, and financial provider as well.

6. Take extra steps for crypto and investment scams

Preserve the offer, claimed returns, account dashboard, wallet addresses, transaction records, and every message. Don't send more funds to pay a "tax," "verification charge," or "withdrawal fee."

File with the FTC and IC3. If the offer involves securities, commodities, or an investment business, also check the official complaint or tip route for the relevant U.S. regulator. A regulator report doesn't replace notice to the exchange, bank, or payment service that handled your money.

Avoid publishing wallet addresses, phone numbers, or personal information in public posts beyond what is necessary to warn others. Give the complete details to official reporting channels instead.

If you're outside the United States

The steps above use U.S. agencies. If you live elsewhere, use your country's official consumer-protection and cybercrime portals, and contact the payment provider in the country where your account is held.

In the United Kingdom, the National Cyber Security Centre's scam-website reporting page accepts reports of suspected scam websites and says it can investigate and remove some of them. A UK report doesn't replace a bank dispute or a police report when money was lost. Reporting powers and procedures differ in other countries, so a U.S. complaint doesn't automatically create a local case.

What may happen after you report

There is no reliable universal takedown deadline or success rate. The result may be:

Keep confirmation numbers and copies of your submissions. If the site remains active, send a focused follow-up that refers to the original report and adds new evidence. Don't repeatedly visit the page to test it. A domain that returns an error may have moved elsewhere, and a warning doesn't prove that your report caused the change.

Can you report a scam website anonymously?

Some forms may accept limited contact information, while government complaints commonly request identifying and incident details. Don't assume that a VPN or Tor makes an official submission anonymous, and don't use a false identity or invent facts.

A safe contact method can help an investigator ask follow-up questions, but share only what the form needs. If you fear retaliation, ask the relevant agency how it handles confidentiality before submitting. An anonymous report may also make it harder to clarify evidence or recover money.

Immediate checklist

  1. Stop interacting with the site and save the exact address, screenshots, messages, and payment records.
  2. Contact your bank, card issuer, or payment service immediately if money is pending or has moved.
  3. Change exposed passwords and secure affected accounts.
  4. File with the FTC for consumer fraud and IC3 for cyber-enabled crime.
  5. Report phishing or malware to Google and Bing, and send a factual abuse report to the host, registrar, or Cloudflare when relevant.
  6. Save confirmation numbers and watch for recovery scams.

If funds are still moving, call the financial institution first. Save its case number, then use the exact URL and evidence in the other reports.